Unrated severityNVD Advisory· Published Oct 30, 2025· Updated Nov 17, 2025
Nagios XI < 5.2.4 SQL Injection in Notification Search
CVE-2016-15050
Description
Nagios XI versions prior to 5.2.4 contain a SQL injection vulnerability in the notification search functionality. User-supplied search parameters were incorporated into SQL statements without adequate parameterization or sanitation, allowing an authenticated user to manipulate database queries. Successful exploitation could disclose or modify notification data and, in some cases, impact the application database more broadly.
Affected products
2- Nagios/XIv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.nagios.com/changelog/nagios-xi/mitrerelease-notespatch
- www.vulncheck.com/advisories/nagios-xi-sqli-in-notification-searchmitrethird-party-advisory
News mentions
0No linked articles in our index yet.